CLI Reference Guide
ACL Configuration Commands
show access-lists
Show all the ACLs.
ip access-list
Define the IP ACL.
ipv6 access-list
Define the extended IPV6 ACL.
deny
Define the deny rule.
permit
Define the permit rule.
Platform
Description
-
permit
One or multiple
permit
conditions are used to determine whether to forward or discard the packet. In
ACL configuration mode, you can modify the existent ACL or configure according to the protocol
details.
Standard IP ACL
[
sn
]
permit
{
source
source-wildcard
|
host
source
|
any
| interface
idx
} [
time-range
tm-range-name
] [
log
]
Extended IP ACL
[
sn
]
permit protocol
source
source-wildcard
destination
destination-wildcard
[
precedence
precedence
] [
tos
tos
] [
fragment
] [
range
lower
upper
] [
time-range
time-range-name
] [
log
]
Extended IP ACLs of some important protocols:
Internet Control Message Protocol (ICMP)
[
sn
]
permit icmp
{
source source-wildcard
|
host
source
|
any
} {
destination
destination-wildcard
|
host
destination
|
any
} [
icmp-type
] [ [
icmp-type
[
icmp-code
] ] | [
icmp-message
] ] [
precedence
precedence
] [
tos
tos
] [
fragment
] [
time-range
time-range-name
]
Transmission Control Protocol (TCP)
[
sn
]
permit tcp
{
source source-wildcard
|
host
source
|
any
} [
operator
port
[
port
] ] {
destination
destination-wildcard
|
host
destination
|
any
} [
operator
port
[
port
] ] [
precedence
precedence
]
[
tos
tos
] [
fragment
] [
range
lower
upper
] [
time-range
time-range-name
] [
match-all
tcp-flag |
established
]
User Datagram Protocol (UDP)
[
sn
]
permit udp
{
source
source -wildcard
|
host
source
|
any
} [
operator
port
[
port
]] {
destination
destination-wildcard
|
host
destination
|
any
} [
operator
port
[
port
]] [
precedence
precedence
] [
tos
tos
] [
fragment
] [
range
lower
upper
] [
time-range
time-range-name
]
Extended MAC ACL
[
sn
]
permit
{
any
|
host
source-mac-address
} {
any
|
host
destination-mac-address
}
[
ethernet-type
][
cos
[
out
] [
inner
in
]]
Extended expert ACL
[
sn
]
permit
[
protocol
| [
ethernet-type
][
cos
[
out
] [
inner
in
]]] [
VID
[
out][
inner
in]
] {
source
source-wildcard
|
host
source
|
any
} {
host
source-
mac
-address
|
any
} {
destination
destination-wildcard
|
host
destination
|
any
} {
host
destination-mac-address
|
any
} [
precedence
precedence
] [
tos
tos
][
fragment
] [
range
lower
upper
] [
time-range
time-range-name
]
When you select the Ethernet-type field or cos field:
[
sn
]
permit
{
ethernet-type|
cos
[
out
] [
inner
in
]} [
VID
[
out
][
inner
in
]] {
source
source-wildcard
|
host
Содержание RG-S2600G-I Series
Страница 1: ...1 CLI Reference Guide RG S2600G I Series Switches RGOS 10 4 3b16...
Страница 5: ...5...
Страница 192: ...CLI ReferenceInterface Configuration Commands Interface Configuration Commands Platform Description...
Страница 452: ...CLI Reference DHCP Configuration Commands commands clear ip dhcp server statistics Delete the DHCP server statistics...
Страница 505: ...CLI Reference TCP Configuration Commands Related commands Command Description...
Страница 513: ...CLI Reference IPv4 REF Configuration Commands Platform description N A Command history Version Description...
Страница 514: ...IP Routing Configuration Commands 1 IP Routing Configuration Commands...
Страница 527: ...Multicast Configuration Commands 1 IGMP Snooping Configuration Commands 2 MLD Snooping Configuration Commands...
Страница 642: ...CLI Reference TACACS Configuration Commands host...
Страница 652: ...CLI Reference 802 1X Configuration Commands Ruijie config if end...
Страница 744: ...CLI Reference CPU Protection Configuration Commands Caution This command is not supported on S3760 series...
Страница 773: ...CLI Reference IPSource Guard Configuration Commands Platform description This command is supported on all switches...
Страница 776: ...CLI Reference ND Snooping Configuration Commands...
Страница 901: ...CLI Reference NFPP Configuration Commands...
Страница 902: ...ACL QOS Configuration Commands 1 ACL Configuration Commands 2 QoS Configuration Commands...
Страница 999: ...CLI Reference RLDP Configuration Command Command mode Privileged EXEC mode...
Страница 1004: ...CLI Reference DLDP Configuration Commands Ruijie config if FastEthernet 0 0 clear dldp 20 1 1 1 10 1 1 1...
Страница 1005: ...CLI Reference DLDP Configuration Commands...
Страница 1146: ...CLI Reference VSU Configuration Commands Examples Ruijie vsu conver to stack Related Commands Command Description N A N A...
Страница 1191: ...CLI Reference Guide RSPAN Configuration Commands Platform Description N A...
Страница 1192: ...CLI Reference Guide...